Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flaw in Snowflake GitHub Workflow Exposed Jira, Patched
August 20, 2026
Critical Citrix NetScaler ADC CVE-2023-3519 lets remote attackers bypass authentication
August 19, 2026
Supply Chain Attacks: How US and EU Enterprises Can Reduce Risk
August 19, 2026
Home/CyberSecurity News/Magecart Hackers Exploit Over 100 Domains to Steal Credit Card Data
CyberSecurity News

Magecart Hackers Exploit Over 100 Domains to Steal Credit Card Data

Key Takeaways A sophisticated Magecart campaign has been observed exploiting over 100 domains to illicitly obtain credit card details. Attackers are employing WebSocket traffic for data exfiltration,...

Emy Elsamnoudy
Emy Elsamnoudy
April 1, 2026 3 Min Read
49 0

Key Takeaways

  • A sophisticated Magecart campaign has been observed exploiting over 100 domains to illicitly obtain credit card details.
  • Attackers are employing WebSocket traffic for data exfiltration, a method that often evades traditional HTTP-based security monitoring.
  • The campaign includes a mobile component, prompting users to download malicious Android APKs under the guise of discounts, localized in multiple languages.
  • This operation represents an evolution in Magecart tactics, shifting from opportunistic injections to a more persistent, infrastructure-backed approach with real-time command and control.

Magecart Evolves: New Campaign Targets Over 100 Domains with Advanced Exfiltration and Mobile Malware

A recent, highly organized Magecart campaign has been uncovered, demonstrating a significant escalation in the sophistication of web skimming attacks. This operation has compromised more than 100 domains, focusing on the theft of credit card information through advanced exfiltration techniques and the distribution of malicious Android applications.

Table Of Content

  • Key Takeaways
  • Magecart Evolves: New Campaign Targets Over 100 Domains with Advanced Exfiltration and Mobile Malware
  • Stealthy Data Exfiltration via WebSockets
  • Mobile Vector Delivers Malicious Android APKs
  • A Shift Towards Persistent, Infrastructure-Driven Operations
  • What You Should Do

Stealthy Data Exfiltration via WebSockets

One of the defining characteristics of this new Magecart variant is its innovative use of WebSockets for data exfiltration. In a documented instance, a command-and-control (C2) server was cleverly camouflaged to appear as a legitimate Redsys domain, specifically redsysgate[.]com. This tactical choice is deliberate, as WebSocket traffic frequently bypasses many conventional HTTP-based security monitoring tools, substantially reducing the likelihood of immediate detection.

The form isn’t static but controlled and manageable

Mobile Vector Delivers Malicious Android APKs

Beyond traditional web skimming, the campaign significantly broadened its attack surface by leveraging the same malicious payload to deliver Android APK files. When users accessed infected online stores via their mobile devices, the embedded script would present a prompt. This prompt enticingly offered discounts or bonuses, contingent on the download and installation of a new application. Crucially, it provided explicit instructions for users to enable installations from “Unknown Sources,” a common prerequisite for sideloading unverified apps.

The global reach and meticulous planning of this mobile component are evident in its localization, with the malicious prompts translated into at least four languages. This multilingual approach underscores that the campaign’s underlying infrastructure was meticulously designed and purpose-built, rather than being a hastily improvised operation.

A Shift Towards Persistent, Infrastructure-Driven Operations

This latest Magecart campaign signals a notable maturation in the threat landscape. It marks a clear departure from the more opportunistic, quick-injection style attacks previously associated with Magecart. Instead, threat actors are now investing in persistent, infrastructure-driven operations that incorporate real-time command-and-control capabilities. This evolution makes these attacks more resilient, harder to detect, and significantly more dangerous for both consumers and businesses.

What You Should Do

  • Monitor Outbound WebSocket Connections: Security teams must prioritize monitoring all outbound WebSocket connections originating from checkout pages and other sensitive areas of their websites.
  • Enforce Strict Content Security Policies (CSP): Implement and rigorously enforce Content Security Policies to restrict which sources can load scripts and other resources on your web pages.
  • Implement JavaScript File Integrity Monitoring: Utilize tools to continuously monitor the integrity of critical JavaScript files, alerting to any unauthorized modifications.
  • Conduct Regular Third-Party Script Audits: Periodically audit all third-party scripts integrated into your website, ensuring they are legitimate and have not been compromised.
  • For Financial Institutions: Enhance fraud detection capabilities for card-not-present transactions and actively participate in threat intelligence sharing to counter these adaptive payment threats.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Oracle WebLogic RCE Flaws Actively Exploited by Attackers

Next Post

Critical Nginx-UI Vulnerability CVE-2023-52074 Lets Attackers Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Leaked Stripe Merchant API Keys Expose Payment and Payout Capabilities
August 19, 2026
AI Voice Phishing Bypasses MFA, Steals Accounts with Fake Banking Pages
August 19, 2026
China Hackers Use Malicious VHD Disguised as JPEG to Deploy QUICAgent Backdoor
August 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us